Thoughts on access control, AI governance, and the security problems worth solving.
Just-in-time access grants permission for a fixed window and takes it back automatically. Why standing access keeps showing up in the 2026 breach reports, why AI agents make it urgent, and how Lutril's policy engine time-boxes access for employees and agents.
OAuth discovery surfaces every app an employee authorized with Sign in with Google or Microsoft. It cannot see the tools people sign up for with a work email and a password. Our new browser extension closes that gap, privacy first.
MCP governance is how you control, authorize, and audit what AI agents can do in your SaaS tools through the Model Context Protocol. What it is, why API keys aren't enough, the MCP gateway pattern, and a checklist to govern AI agent access.
Most employees already use AI tools your security team never approved. Shadow AI is shadow IT that reads your data and acts on your systems. Here is why it spreads, what it costs, and how to govern it instead of banning it.
Your security stack controls who can access your SaaS tools. It has no idea your AI agents even exist. The problem, the gaps, and what governance for agents actually looks like.
AI agents need identity, policy enforcement, audit logs, and a kill switch before they touch your SaaS stack. That infrastructure has a name. Here is what it is and how it works.
When an employee who built or owned an AI agent departs, the agent keeps running. It still has access. Nobody owns it. Here is how to handle AI agent access during employee offboarding.
Okta and Azure AD are excellent at managing human identity. Neither was designed for AI agents. Here is where each fits, where the gaps are, and why you probably need all three.
Step-by-step: register a Claude agent in Lutril, connect Slack as an MCP app, bind the integration with read/write scope, and wire it into Claude. Every tool call logged, kill switch included.
Disabling an Okta account is not offboarding. 41% of employees keep access to company systems after leaving. Here is what complete access revocation actually requires.
The average company uses 3x more SaaS tools than IT knows about. Shadow IT is not a policy problem. It is a structural one. Here is why it happens, what risk it creates, and how to manage it.
Most access reviews are a formality. Managers approve without context, shadow IT goes unreviewed, and evidence is thin. Here is what SOC 2 and ISO 27001 actually require.